PkgRadar

PyPI · pypi.org

structflo-cser

Remote Payload: matched "wget "

Why PkgRadar flagged 0.4.1

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · structflo_cser-0.4.1/asset_scripts/download_chembl.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.1Review122026-06-05
0.4.0Review122026-06-01
0.3.0Review122026-05-29

Block this in CI

PkgRadar gates structflo-cser (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi structflo-cser==0.4.1